First published: Wed Jan 09 2019(Updated: )
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
NEC Aterm WF1200CR firmware | <=1.1.1 | |
NEC Aterm WF1200CR | ||
Nec Aterm Wg1200cr Firmware | <=1.0.1 | |
Nec Aterm Wg1200cr |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16194 is a vulnerability that allows authenticated attackers to execute arbitrary OS commands on Aterm WF1200CR and Aterm WG1200CR devices.
The severity of CVE-2018-16194 is rated as critical with a CVSS score of 7.2.
Aterm WF1200CR firmware versions up to and including 1.1.1 and Aterm WG1200CR firmware versions up to and including 1.0.1 are affected by CVE-2018-16194.
To mitigate the CVE-2018-16194 vulnerability, it is recommended to update the Aterm WF1200CR firmware to version 1.1.2 or later and the Aterm WG1200CR firmware to version 1.0.2 or later.
You can find more information about CVE-2018-16194 on the NEC security advisory page (https://jpn.nec.com/security-info/secinfo/nv18-021.html) and the JVN website (https://jvn.jp/en/jp/JVN87535892/index.html).